We will not pursue or support legal action against security researchers who discover and report vulnerabilities in good faith and in accordance with this policy.
Research and reporting carried out consistently with this policy are considered authorised. We ask that you make a good-faith effort to avoid privacy violations, data destruction, and interruption of our services; that you access or modify only the minimum data needed to demonstrate the issue; and that you give us reasonable time to remediate before any public disclosure.